TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

Tell HN: Rise in AWS accounts getting hacked and owner being stuck with the bill

112 点作者 Kpourdeilami超过 3 年前
I have been seeing a lot of posts on Reddit and other forums of mostly students setting up an AWS account only for them to be hacked and account owner being stuck with a significant bill.<p>Most likely scenario is hackers are trying leaked username&#x2F;password pairs from other breaches against AWS and gaining access to those accounts.<p>They then spin up EC2 instances in all sorts of regions on the compromised accounts<p>PSA set up MFA on your account if you haven&#x27;t already.<p>Some examples:<p><a href="https:&#x2F;&#x2F;www.reddit.com&#x2F;r&#x2F;aws&#x2F;comments&#x2F;rv3lm5&#x2F;i_lost_55k_from_hackers&#x2F;" rel="nofollow">https:&#x2F;&#x2F;www.reddit.com&#x2F;r&#x2F;aws&#x2F;comments&#x2F;rv3lm5&#x2F;i_lost_55k_from...</a><p><a href="https:&#x2F;&#x2F;www.reddit.com&#x2F;r&#x2F;aws&#x2F;comments&#x2F;rvbncu&#x2F;account_hacked_unable_to_sign_in_4000_in&#x2F;" rel="nofollow">https:&#x2F;&#x2F;www.reddit.com&#x2F;r&#x2F;aws&#x2F;comments&#x2F;rvbncu&#x2F;account_hacked_...</a><p><a href="https:&#x2F;&#x2F;www.reddit.com&#x2F;r&#x2F;aws&#x2F;comments&#x2F;qx8i02&#x2F;got_hacked_and_found_a_30k_bill_please_turn_on&#x2F;" rel="nofollow">https:&#x2F;&#x2F;www.reddit.com&#x2F;r&#x2F;aws&#x2F;comments&#x2F;qx8i02&#x2F;got_hacked_and_...</a><p><a href="https:&#x2F;&#x2F;www.reddit.com&#x2F;r&#x2F;aws&#x2F;comments&#x2F;rv4mnq&#x2F;my_account_was_hacked_and_now_my_bill_is_over&#x2F;" rel="nofollow">https:&#x2F;&#x2F;www.reddit.com&#x2F;r&#x2F;aws&#x2F;comments&#x2F;rv4mnq&#x2F;my_account_was_...</a>

18 条评论

ujetin超过 3 年前
I deleted my AWS account yesterday. It is obviously catered towards large organisations - very complicated tools and pricing that I couldn&#x27;t really fit into my use case. I tried to just shut down the services that were using money but wasn&#x27;t even sure I had found them all so I just closed the whole account.<p>I don&#x27;t even like the idea of any of this stuff. I want to run my own little raspberry pi server or whatever, it seems much more fun and startupish than aws, which appears to be all of the corporate stuff I left (AIMs etc). This is funny because I remember AWS being thought of as great for &quot;just experimenting with stuff&quot;.
评论 #29790362 未加载
评论 #29790127 未加载
评论 #29789882 未加载
评论 #29791331 未加载
评论 #29789842 未加载
评论 #29790210 未加载
评论 #29789750 未加载
评论 #29792568 未加载
评论 #29792020 未加载
评论 #29792700 未加载
andrewguenther超过 3 年前
MFA needs to be forced on by default for all new accounts created with the UI. It is utterly irresponsible for AWS to not do this. People always counter with &quot;you should know better!&quot; But AWS markets itself to college kids. People were all up in arms and Robinhood allowing 18 year olds to create accounts which could result in unbounded losses, but AWS somehow gets a pass?
jackson1442超过 3 年前
@aws, why not mandate MFA for a root user? in child org accounts where this is less feasible, you could allow access to the root user only from the parent account, no direct login at all.
评论 #29790026 未加载
评论 #29790227 未加载
评论 #29789680 未加载
BackBlast超过 3 年前
I migrated off AWS in December and closed my account. With the outages, they are likely looking at revenue shortfalls. Outages don&#x27;t scare me, but their billing practices are already uncomfortable. This may make them prone to be more stingy about bill forgiveness. Bill forgiveness is inherent in the unsafe billing model which makes even having the account open even more of a huge liability.<p>I&#x27;m done.
javagram超过 3 年前
Good reminder to completely close my AWS account. I have TOTP MFA on it but having a AWS account that had the same root login as my Amazon retail account was risky and a mistake from the beginning. Luckily I haven&#x27;t used it for anything in years so it was as simple as following the &quot;Close account&quot; procedure.<p>I&#x27;ll use Digital Ocean for anything small if I need to spin up a server in the future.
sgarg26超过 3 年前
This happened to me. I had a 9k bill and I got hacked and stuck with it on my personal account. I gave AWS $100k business and that did not matter through being a decision maker at a startup I work at. AWS does not care about your business unless you are going to IPO. True story. Feel free to message me at Sgargconsulting --&gt; GMAIL
vmception超过 3 年前
This happened to me, the bill was so ridiculous that I wasnt even bothered by it. It got voided by aws support as predicted.<p>MFA does not prevent this. Its IAM keys.
评论 #29791266 未加载
评论 #29790687 未加载
anothernewdude超过 3 年前
If only they had some kind of charge limiting on accounts like their customers have been asking for years now.
Aeolun超过 3 年前
I find it hard to believe AWS would try to suck blood from a stone. I’m willing to believe they get a 55k bill, but do they actually end up paying those?
评论 #29789726 未加载
评论 #29789627 未加载
评论 #29789621 未加载
quickthrower2超过 3 年前
Thanks! You&#x27;ve reminded me to close my hobby AWS account. I will do that now.<p>Edit: Done! Was quite easy. Luckily I had no services running or needed.
blibble超过 3 年前
their hardware MFA functionality is worse than useless<p>it only permits a single hardware token to be registered to an account<p>so good luck if you misplace or break your hardware token
评论 #29789988 未加载
评论 #29789979 未加载
评论 #29789990 未加载
评论 #29790042 未加载
jeppesen-io超过 3 年前
MFA is good advice<p>Also, I&#x27;d create a IAM user and severely limit your usage of the root account, and over time stop using the root completely.
staticassertion超过 3 年前
Well, yeah, of course they&#x27;re stuck with the bill. I feel like people think AWS is supposed to have infinite guard rails regardless of what the engineers using it do, like when people write code that infinite loops and it blows up their bill.<p>AWS gives money back in a lot of cases that I think they legitimately aren&#x27;t responsible for.<p>I don&#x27;t know that other cloud providers are going to do any better - an attacker who has your credentials and spins up 10&#x27;s of thousands of dollars of infra will cost you thousands of dollars.<p>I&#x27;ll certainly echo the advice for 2FA but, more importantly, use a strong, unique password.
评论 #29790080 未加载
评论 #29790175 未加载
评论 #29790332 未加载
评论 #29790054 未加载
smackeyacky超过 3 年前
I know it&#x27;s easy to get lazy about checking your AWS billing dashboard but I do it once a week - you can set up alerts and whatnot but I find it easier just to go look at the current usage to make sure nothing has gone awry.
评论 #29792744 未加载
评论 #29790431 未加载
spekcular超过 3 年前
The fact that AWS has no way to limit billing seems insane to me. Your only recourse for an accidental (or malicious) overcharge is beg customer support. It&#x27;s an incredible liability.
评论 #29790173 未加载
评论 #29789884 未加载
评论 #29790702 未加载
评论 #29790238 未加载
评论 #29790079 未加载
aborsy超过 3 年前
Services like Lightsail have caps and flat fees. AWS needs more of this.
halilduygulu超过 3 年前
please, everyone enable MFA and billing alerts in your accounts. do not commit access&amp;secret keys to github.
edoceo超过 3 年前
Can you connect CloudWatch to your billing so you&#x27;d get an alert on some kind of spikes?